2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-35642MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bryan Hadaw...
CVE-2024-35641MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GregRoss Ju...
CVE-2024-37031MEDIUM6.1The Active Admin (aka activeadmin) framework before 3.2.2 for Ruby on Rails allows stored XSS in certain situations wher...
CVE-2024-20075MEDIUM6.7In eemgpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of...
CVE-2024-20074MEDIUM6.6In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2024-20073MEDIUM6.6In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local esca...
CVE-2024-20072MEDIUM6.6In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escal...
CVE-2024-20071MEDIUM4.4In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local inform...
CVE-2024-20070MEDIUM5.1In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establ...
CVE-2024-20069MEDIUM6.5In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade che...
CVE-2024-20068MEDIUM5.9In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2024-20065MEDIUM4In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf...
CVE-2024-36392MEDIUM6.1MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-5587MEDIUM6.9A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown functi...
CVE-2024-4344MEDIUM4.3The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Sit...
CVE-2024-35647MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Noti...
CVE-2024-35646MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnens...
CVE-2024-35645MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar R...
CVE-2024-3200MEDIUM6.5The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode ...
CVE-2024-35636MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uplo...
CVE-2024-2295MEDIUM6.4The Contact Form Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [xyz-cfm-for...
CVE-2024-2506MEDIUM6.4The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to St...
CVE-2024-1324MEDIUM5.3The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili...
CVE-2024-5501MEDIUM6.4The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-4342MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now